April Patch Tuesday Lands With 167 Microsoft Fixes, SharePoint Zero-Day Under Attack

BlueHammer Defender bug goes public, Adobe Reader flaw exploited since November, and Chrome ships its fourth zero-day of the year.

ThreatVectr Newsdesk· 2 min read
April Patch Tuesday Lands With 167 Microsoft Fixes, SharePoint Zero-Day Under Attack
Share

If you manage Windows fleets, today is a long one. Microsoft shipped fixes for 167 vulnerabilities on April Patch Tuesday, including an actively exploited SharePoint Server spoofing flaw tracked as CVE-2026-32201 and a publicly disclosed Windows Defender privilege escalation nicknamed BlueHammer. Adobe Reader and Google Chrome also pushed emergency updates, both for bugs already being used in the wild.

Start with SharePoint. The spoofing bug lets an attacker present falsified content inside what users believe is a trusted internal site. Mike Walters, president and co-founder of Action1, said the flaw is well-suited to phishing pivots and social engineering inside compromised tenants. Active exploitation is already confirmed. If your SharePoint Server is internet-facing, treat this as the first thing on the list.

BlueHammer, tracked as CVE-2026-33825, is the one that will get the hallway chatter. The finder dropped working exploit code after losing patience with Microsoft's triage timeline (a pattern we keep seeing this year). Will Dormann, senior principal vulnerability analyst at Tharros, confirmed the public exploit no longer fires against patched hosts. Good. Patch anyway, because anyone who weaponised it before today is not going to throw the code away.

The Adobe Reader bug is arguably the nastier story. Satnam Narang, senior staff research engineer at Tenable, said CVE-2026-34621 has indicators of in-the-wild abuse going back to November 2025. That is roughly five months of quiet RCE against a product sitting on millions of endpoints. If your endpoint management does not push Reader updates automatically, fix that this week.

Why 167 CVEs in one month? Adam Barnett, lead software engineer at Rapid7, noted that nearly 60 of them are browser bugs republished from Chromium upstream, and credited expanding AI-assisted bug discovery for the volume. Expect the numbers to keep climbing.

One housekeeping note. Restart your browser. Chrome's fourth zero-day of 2026, CVE-2026-5281, only gets patched after a full relaunch, and tab hoarders (you know who you are) tend to run unpatched builds for weeks.

Defender checklist for this cycle:

  1. Patch internet-facing SharePoint Server first. CVE-2026-32201 is being exploited now.
  2. Push the Windows cumulative update to kill BlueHammer before opportunistic actors reuse the public PoC.
  3. Force an Adobe Reader update across all endpoints and audit for signs of exploitation back to November 2025.
  4. Restart every browser on managed devices, or push a forced relaunch policy, to land the Chrome fix.
  5. Pull your April vulnerability report into next week's change review and flag any host that skipped the cycle.
© 2026 Threat Vectr